Junglewise Threat Intelligence

CVE-2019-25679: Realterm RealTerm Serial Terminal SEH buffer overflow in Echo Port tab

CVE-2019-25679 · Severity: high · CVSS 7.8 · Published 2026-04-05

Executive brief

RealTerm Serial Terminal, a tool used by engineers to debug data streams and serial communications, contains a security flaw in its Echo Port configuration. An attacker can gain full control over a user's computer if the user is tricked into pasting a specially crafted string of text into the application's Port field. This could lead to the unauthorized installation of software, data theft, or complete system compromise.

Technical details

A stack-based buffer overflow exists in RealTerm Serial Terminal version 2.0.0.70 and earlier. The vulnerability is located in the 'Echo Port' tab within the 'Port' input field. By supplying an overly long string to this field and clicking the 'Change' button, an attacker can overwrite the Structured Exception Handler (SEH) record. Exploitation requires local access and user interaction (pasting the payload). A successful exploit using a POP POP RET gadget chain allows for arbitrary shellcode execution with the privileges of the application user. While a version 3.0 Beta is in development, a specific patch for this legacy vulnerability in the 2.0.x branch is not explicitly confirmed.

Affected products

  • Realterm RealTerm Serial Terminal 2.0.0.70 and earlier (including 1.11.2)

Timeline

  • 2019-02-21: disclosed: Original exploit code published on Exploit-DB
  • 2026-04-05: advisory: NVD/VulnCheck advisory published

References